Data Breaches

Twilio Confirms Data Breach After Hackers Leak 33M Authy User Phone Numbers

Twilio has confirmed a data breach after hackers leaked 33 million phone numbers associated with the Authy app.

Twilio

Twilio this week confirmed suffering a data breach after hackers leaked 33 million phone numbers associated with the Authy application.

The notorious ShinyHunters hackers announced on the relaunched BreachForums website in late June that they were leaking 33 million random phone numbers associated with Twilio’s two-factor authentication app Authy.

The leaked information also included account IDs and some other non-personal data associated with Authy users. 

In a security alert posted on its website, Twilio confirmed the data breach.

“Twilio has detected that threat actors were able to identify data associated with Authy accounts, including phone numbers, due to an unauthenticated endpoint. We have taken action to secure this endpoint and no longer allow unauthenticated requests,” the company said.

Twilio found no evidence that the hackers gained access to its systems or that they obtained other sensitive data, but as a precaution urged Authy users to install the latest Android and iOS security updates. 

Advertisement. Scroll to continue reading.

“While Authy accounts are not compromised, threat actors may try to use the phone number associated with Authy accounts for phishing and smishing attacks; we encourage all Authy users to stay diligent and have heightened awareness around the texts they are receiving,” Twilio said.

Related: Twilio, HashiCorp Among Codecov Supply Chain Hack Victims

Related: Twilio Says Employees Targeted in Separate Smishing, Vishing Attacks

Related: Okta Says Customer Data Compromised in Twilio Hack

Related: Twilio Hacked After Employees Tricked Into Giving Up Login Credentials

Related Content

Data Breaches

A cyberattack caused disruptions at the toy and game giant earlier this year and the company is now disclosing a data breach.

Data Breaches

Nutex Health has informed the SEC that it recently detected unauthorized access and data exfiltration.

Data Breaches

The private equity firm appears to have been targeted as part of a campaign focusing on major financial companies.

Data Breaches

The cybercrime gang has listed major companies such as Shell, Philips, Fiserv, Zebra, Mindray, and Largan Precision.

Data Breaches

The data breach was initially believed to affect roughly 350,000 people, but the HHS breach tracker shows a far bigger impact.

Data Breaches

Hackers stole names, addresses, phone numbers, Social Security numbers, and financial information from a third-party platform.

Data Breaches

Hackers used compromised credentials to access enterprise and personal tax-related data.

Data Breaches

Hackers exploited a vulnerability in the order-tracking function of a plugin to access SafePal customer information.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version